Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-34256— Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass

EPSS 0.21% · P43
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-34256

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用硬编码的密码学密钥
Source: NVD (National Vulnerability Database)
Vulnerability Title
Advantech WISE-DeviceOn Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Advantech WISE-DeviceOn Server是中国台湾研华(Advantech)公司的一个物联网设备管理平台软件。 Advantech WISE-DeviceOn Server 5.4之前版本存在安全漏洞,该漏洞源于使用硬编码加密密钥,可能导致远程攻击者冒充任意账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Advantech Co., Ltd.WISE-DeviceOn Server 0 ~ 5.4.0 -

II. Public POCs for CVE-2025-34256

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-34256

登录查看更多情报信息。

Same Patch Batch · Advantech Co., Ltd. · 2025-12-05 · 11 CVEs total

CVE-2025-34260Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/schedule
CVE-2025-34261Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/
CVE-2025-34266Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/men
CVE-2025-34264Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}
CVE-2025-34262Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}
CVE-2025-34258Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/plan
CVE-2025-34257Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined
CVE-2025-34263Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards
CVE-2025-34265Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines
CVE-2025-34259Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/building

IV. Related Vulnerabilities

V. Comments for CVE-2025-34256

No comments yet


Leave a comment